oxzifbeh.dll

jcentertainment corporation

The library oxzifbeh.dll has been detected as malware by 19 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘OXzifbeH’.
Publisher:
jcentertainment corporation  (signed and verified)

MD5:
71b4bcdd93d28f8e42798d9c7e32bc67

SHA-1:
860e46e5ab085df96d7ef4e2dfd701df06ade65a

SHA-256:
9a613fec8c67a98c99b5258d75dbcb9b936b33cbc2eab3519d44b4c6f10fe64c

Scanner detections:
19 / 68

Status:
Malware

Analysis date:
4/26/2024 11:54:24 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2329253
25

AhnLab V3 Security
Trojan/Win32.Banki
2015.05.03

AVG
Inject2
2018.0.2503

Baidu Antivirus
Trojan.Win32.Injector
4.0.3.17110

Bitdefender
Trojan.GenericKD.2329253
1.0.20.50

Dr.Web
Trojan.Inject1.54905
9.0.1.010

Emsisoft Anti-Malware
Trojan.GenericKD.2329253
8.17.01.10.08

ESET NOD32
Win32/Injector.BWXX (variant)
11.11565

Fortinet FortiGate
W32/BWXX!tr
1/10/2017

F-Secure
Trojan.GenericKD.2329253
11.2017-10-01_3

G Data
Trojan.GenericKD.2329253
17.1.25

K7 AntiVirus
Trojan
13.203.15783

McAfee
RDN/Generic.grp!ig
5600.6159

MicroWorld eScan
Trojan.GenericKD.2329253
18.0.0.30

NANO AntiVirus
Trojan.Win32.Inject1.drbonj
0.30.24.1357

Norman
Suspicious_Gen4.IHEIJ
11.20170110

nProtect
Trojan.GenericKD.2329253
15.04.30.01

Trend Micro House Call
Suspicious_GEN.F47V0428
7.2.10

ViRobot
Trojan.Win32.S.Agent.74696[h]
2014.3.20.0

File size:
72.9 KB (74,696 bytes)

File type:
Dynamic link library (Win32 DLL)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/24/2012 9:00:00 AM

Valid to:
1/24/2014 8:59:59 AM

Subject:
CN=jcentertainment corporation, OU=Security Tech Team, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=jcentertainment corporation, L=Seongnam, S=Gyeonggi, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
186E59C52F0186768F03E6D28BF9E45D

File PE Metadata
Compilation timestamp:
4/12/2015 1:28:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0xA040

Entry point:
B8, 10, E9, 03, 10, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 0A, 54, 88, 57, 1E, EE, F5, 7F, ED, 21, 87, 3C, DF, E4, 6E, 90, 6B, 68, FC, 49, FD, 13, 62, 4C, 00, 2A, 16, FD, 09, 4C, 70, B9, AF, F9, DF, 7A, AE, 3A, CF, 5B, CC, DC, BC, 57, 0B, 58, D2, 3A, 8F, 2A, 52, CF, D6, B0, 58, E1, 89, FB, D7, 9D, FF, 8A, 66, 21, F9, 61, 38, 86, 0E, 78, 20, D4, C9, F2, 78, 13, F6, F3, 2C, 9E, 50, C0, 8E, 02, 30, 23, 0A, 8E, D0, A7, 3C, 99, 5F...
 
[+]

Entropy:
7.8901

Packer / compiler:
PECompact v2

Code size:
44 KB (45,056 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
OXzifbeH

Command:
rundll32.exe C:\4b5aox\oxzifbeh.dll,honshuan


Remove oxzifbeh.dll - Powered by Reason Core Security